Privacy Policy
Effective date: 15 July 2026 | Last updated: 15 July 2026
Policy scope
This Privacy Policy applies to the DACORIS CRIS public website, product interfaces, demonstrations, support channels and related communications operated by DACORIS Group or the contracting DACORIS entity identified in an applicable agreement. An institutional customer may issue an additional privacy notice governing its own use of DACORIS CRIS.
1. Who we are
DACORIS CRIS is a research information management and institutional research intelligence platform offered as part of DACORIS Group. In this Privacy Policy, "DACORIS", "we", "us" and "our" refer to DACORIS Group and the applicable contracting entity identified in the relevant proposal, order form or service agreement.
Contact: info@dacoris.com; +254 732 436 199; based at Strathmore University, Nairobi, Kenya.
2. When this Policy applies
This Policy applies when you visit our website, request information or a demonstration, create or use an account, communicate with our support team, attend a DACORIS event, receive marketing communications, or otherwise interact with DACORIS CRIS.
Where an institution provides DACORIS CRIS to its staff, students, researchers or partners, that institution will ordinarily determine why and how institutional data is processed. In that context, the institution is typically the data controller and DACORIS is typically a data processor acting on documented instructions. The applicable agreement may define the roles differently for specific processing activities.
3. Personal data we may collect
Account and identity data: name, title, institutional affiliation, department, role, username, contact details, profile photograph and authentication information.
Research and professional-profile data: areas of expertise, qualifications, identifiers, research interests, affiliations, projects, grants, proposals, publications, datasets, collaborations, skills and other portfolio information.
Institutional workflow data: approvals, comments, review actions, ethics records, postgraduate milestones, supervision records, training records, partnership responsibilities, assigned tasks and audit history.
Content you provide: documents, proposal text, manuscripts, attachments, datasets, support requests, survey responses and other information entered or uploaded into the service.
Technical and usage data: device and browser information, IP address, timestamps, diagnostic logs, security events, pages or features used, session information and cookie or similar-technology data.
Communications and commercial data: enquiry details, demonstration requests, meeting records, proposals, contracts, billing contacts, payment status and correspondence.
Integration data: information retrieved from or sent to systems that you or your institution authorise, such as identity systems, repositories, scholarly databases, reference managers, finance systems, student systems or other enterprise applications.
4. How we collect personal data
Directly from you when you register, complete a form, upload information, request a demonstration, contact support or communicate with us.
From your institution or another authorised administrator when they provision your account, assign a role or import institutional records.
From authorised integrations and public scholarly sources where the institution or user requests or permits import, discovery or matching.
Automatically through logs, cookies and similar technologies when you use the website or platform.
From partners, event organisers or referral contacts where they lawfully share your professional contact information for a relevant business purpose.
5. Why we process personal data and our lawful bases
To provide, configure, secure, maintain and support DACORIS CRIS and perform our contractual obligations.
To authenticate users, administer accounts, enforce permissions, detect misuse and protect the confidentiality, integrity and availability of the service.
To support institutional research workflows, reporting and analytics in accordance with customer instructions.
To respond to enquiries, arrange demonstrations, prepare proposals, manage contracts and provide customer service.
To improve usability, reliability, functionality, documentation and service performance.
To comply with legal obligations, lawful requests, tax and accounting requirements, and to establish, exercise or defend legal claims.
To send relevant service notices and, where permitted, marketing communications. You may opt out of non-essential marketing at any time.
Depending on the context, processing may be based on performance of a contract, compliance with a legal obligation, legitimate interests, consent, a task carried out in the public interest, or another lawful basis available under applicable law. The institutional customer is responsible for identifying the lawful basis for processing it controls.
6. Sensitive and special-category data
DACORIS CRIS may be configured to hold information that is sensitive or receives special legal protection, including ethics records, research-participant information, health-related research information or other restricted institutional content. Such processing must be specifically authorised, necessary for a defined purpose, supported by an appropriate lawful condition and protected through proportionate access and security controls.
Customers should not upload directly identifiable participant-level or patient-level data unless the agreed service architecture, contract, approvals, notices, consent or other lawful basis, security controls and data-management plan expressly permit that processing.
7. How we share personal data
With the institutional customer and authorised users according to configured roles and permissions.
With service providers and subprocessors that support hosting, communications, security, support, analytics, payment administration or other agreed service functions, subject to appropriate contractual safeguards.
With authorised integration providers when a user or institution connects DACORIS CRIS to another system.
With professional advisers, auditors, insurers, regulators, courts or public authorities where necessary and lawful.
In connection with a corporate transaction, restructuring or transfer of business, subject to confidentiality and applicable legal safeguards.
We do not sell personal data. We do not disclose institutional research content for unrelated advertising.
8. International data transfers
Depending on the selected hosting environment, support arrangement and integrations, personal data may be processed in a country other than the country in which it was collected. Before such transfers, DACORIS and the institutional customer should document the data locations, relevant recipients and appropriate legal safeguards. These may include adequacy decisions, contractual clauses, consent where legally valid, or another transfer mechanism recognised by applicable law.
9. Data retention
We retain personal data for as long as reasonably necessary for the purpose for which it was collected, to provide the service, comply with legal and contractual obligations, resolve disputes, maintain security records and enforce agreements. Institutional content is retained according to the customer agreement and configured retention rules.
At the end of the service, DACORIS will handle return, export, archival or deletion of customer data according to the applicable contract, legal requirements and technical feasibility. Backup copies may remain for a limited period until they are securely overwritten under the backup cycle.
10. Information security
We use technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. Measures may include access controls, authentication safeguards, encryption, logging, monitoring, backups, secure development, vulnerability management, incident response and staff confidentiality obligations. No system can guarantee absolute security; users and institutions must also protect credentials, devices, integrations and exported data.
11. Your data-protection rights
Request access to personal data held about you.
Request correction of inaccurate or incomplete data.
Request deletion where the legal conditions are met.
Object to or request restriction of certain processing.
Request portability where applicable.
Withdraw consent where processing is based on consent, without affecting earlier lawful processing.
Opt out of non-essential marketing communications.
Lodge a complaint with the relevant data-protection authority, including the Office of the Data Protection Commissioner in Kenya where applicable.
When DACORIS processes data solely on behalf of an institutional customer, we may refer your request to that customer or assist the customer to respond.
12. Cookies and similar technologies
Our website and platform may use essential cookies or similar technologies for authentication, session continuity, security, preferences and service operation. We may use optional analytics technologies to understand performance and improve user experience. Where required, optional cookies will be used only after appropriate notice and consent. Browser settings may be used to block or delete cookies, although essential features may then operate incorrectly.
13. Automated matching and analytics
DACORIS CRIS may use automated rules or analytical methods to match funding opportunities to profiles, highlight incomplete requirements, generate risk flags or produce portfolio insights. These functions are intended to support human decision-making. Unless expressly agreed and lawfully configured, DACORIS CRIS should not be used to make solely automated decisions that produce legal or similarly significant effects on an individual.
14. Children and minors
DACORIS CRIS is primarily intended for institutions, adult researchers, staff and postgraduate users. Where an institution uses the service in a context involving a minor, the institution must ensure that the processing is lawful, appropriately notified, necessary, age-appropriate and supported by required consent or other legal authority.
15. Third-party links and services
The service may link to or integrate with third-party websites, databases or tools. Their privacy practices are governed by their own notices and contracts. DACORIS is not responsible for a third party's independent processing, but will apply reasonable diligence and contractual safeguards where that third party acts as a DACORIS subprocessor.
16. Changes to this Policy
We may update this Policy to reflect changes in law, technology, services or operating practices. We will publish the revised version with an updated effective date and provide additional notice where a change is material or legally required.
17. Contact and complaints
For privacy questions, data-subject requests or complaints, contact info@dacoris.com and use the subject line "Privacy Request". You may also call +254 732 436 199. Please provide enough information for us to verify the request and identify the relevant institutional account. You may lodge a complaint with the competent data-protection authority if you believe your personal data has been processed unlawfully.